You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

咨询:能否配置Grafana LDAP组关联Orgs/Teams实现新用户自动归属

Absolutely! You can map LDAP groups to Grafana organizations (Orgs) and teams, so new users from those LDAP groups get automatically added to the corresponding Orgs/Teams on their first login. Let me break down how to set this up for both scenarios:

Mapping LDAP Groups to Grafana Organizations

This is handled directly in Grafana's LDAP configuration file (usually located at conf/ldap.toml). Here's how to configure it:

  1. First, ensure your LDAP server attributes are correctly set
    In the [servers.attributes] section, make sure you've defined the attribute that holds group memberships (most commonly memberOf):

    [servers.attributes]
      name = "givenName"
      surname = "sn"
      username = "sAMAccountName"
      member_of = "memberOf" # This is key for group mappings
      email =  "mail"
    
  2. Add group-to-organization mappings
    Under the [servers.group_mappings] section, create entries that link LDAP groups to specific Grafana organizations and roles. For example:

    [[servers.group_mappings]]
      group_dn = "cn=grafana-admins,ou=groups,dc=example,dc=com"
      org_role = "Admin"
      org_id = 1 # Replace with your target organization's ID
    
    [[servers.group_mappings]]
      group_dn = "cn=grafana-editors,ou=groups,dc=example,dc=com"
      org_role = "Editor"
      org_id = 1
    
    [[servers.group_mappings]]
      group_dn = "cn=grafana-viewers,ou=groups,dc=example,dc=com"
      org_role = "Viewer"
      org_id = 2 # Map to a different organization
    
    • group_dn: The full Distinguished Name of your LDAP group
    • org_role: The role the user will get in the organization (options: Admin, Editor, Viewer)
    • org_id: The numeric ID of the Grafana organization you want to link to

When a new user from these LDAP groups logs in for the first time, Grafana will automatically create their account and add them to the specified organization with the assigned role.

Mapping LDAP Groups to Grafana Teams

For team mappings, you'll use Grafana's provisioning feature (since LDAP config alone doesn't handle team sync). Here's the step-by-step:

  1. Create a team provisioning file
    Navigate to the provisioning teams directory (default: conf/provisioning/teams/) and create a YAML file (e.g., ldap-team-sync.yaml). Add content like this:

    apiVersion: 1
    
    teams:
      - name: "Data Engineering Team"
        uid: "data-eng-team"
        orgId: 1 # Must match the organization ID where the team exists
        members:
          - query: "memberOf=cn=data-engineers,ou=groups,dc=example,dc=com"
            group: "LDAP"
      - name: "DevOps Team"
        uid: "devops-team"
        orgId: 1
        members:
          - query: "memberOf=cn=devops,ou=groups,dc=example,dc=com"
            group: "LDAP"
    
    • name: The name of your Grafana team
    • uid: A unique identifier for the team (used to avoid duplicates during provisioning)
    • orgId: The organization ID the team belongs to
    • query: The LDAP group membership filter (matches users in the specified LDAP group)
    • group: "LDAP": Tells Grafana to sync users from the LDAP group into this team
  2. Verify provisioning is enabled
    Check your conf/defaults.ini (or custom conf/custom.ini) to ensure team provisioning is turned on:

    [provisioning]
      teams = true
    
  3. Restart Grafana
    After saving the provisioning file, restart your Grafana server to apply the changes.

From now on, any user in the mapped LDAP groups (whether new or existing) will be automatically added to the corresponding Grafana team on their next login.

Quick Notes
  • Always back up your configuration files before making changes.
  • For existing users, their organization roles and team memberships will update on their next login after you modify the LDAP/provisioning configs.
  • You can combine both methods (Org and Team mappings) to fully automate user access based on LDAP groups.

内容的提问来源于stack exchange,提问作者ScipioAfricanus

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 09:20:34